CVE-2026-14790

A flaw has been found in GPAC 26.02.0. This affects the function nhmldump_send_frame of the file src/filters/write_nhml.c of the component Media File Handler. Executing a manipulation can lead to null pointer dereference. The attack requires local access. The exploit has been published and may be used. This patch is called bd1d94e70e3bef364c07c5a1d94eca5c9f56e160. A patch should be applied to remediate this issue. The project explains: "I would consider most of these more as bugs than vulns but anyway they're good to fix".
Configurations

No configuration.

History

06 Jul 2026, 16:16

Type Values Removed Values Added
References () https://vuldb.com/submit/850391 - () https://vuldb.com/submit/850391 -

06 Jul 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-06 03:16

Updated : 2026-07-06 18:02


NVD link : CVE-2026-14790

Mitre link : CVE-2026-14790

CVE.ORG link : CVE-2026-14790


JSON object : View

Products Affected

No product.

CWE
CWE-404

Improper Resource Shutdown or Release

CWE-476

NULL Pointer Dereference